Lucene search

K
redhatRedHatRHSA-2014:1891
HistoryNov 24, 2014 - 8:43 p.m.

(RHSA-2014:1891) Important: Red Hat JBoss BRMS 6.0.3 security update

2014-11-2420:43:48
access.redhat.com
16

0.004 Low

EPSS

Percentile

74.9%

Red Hat JBoss BRMS is a business rules management system for the
management, storage, creation, modification, and deployment of JBoss Rules.

This roll up patch serves as a cumulative upgrade for Red Hat JBoss BRMS
6.0.3, and includes bug fixes and enhancements. It includes various bug
fixes, which are listed in the README file included with the patch files.

The following security issues are fixed with this release:

It was discovered that Jakarta Commons HttpClient incorrectly extracted the
host name from an X.509 certificate subject’s Common Name (CN) field.
A man-in-the-middle attacker could use this flaw to spoof an SSL server
using a specially crafted X.509 certificate. (CVE-2012-6153, CVE-2014-3577)

The CVE-2012-6153 issue was discovered by Florian Weimer of Red Hat
Product Security.

All users of Red Hat JBoss BRMS 6.0.3 as provided from the Red Hat Customer
Portal are advised to apply this roll up patch.